Trust

Security

Anvil holds commercially sensitive material: client briefs, costs and margins. Here is how that is protected.

Last updated 29 August 2026

Authentication

Accounts use email and password authentication with a managed provider. Sessions are short-lived and refreshed with rotating tokens. Password reset runs through an emailed one-time link.

Data isolation

Every table is protected by row-level security scoped to the owning account, so one account cannot read or write another account's proposals, uploads or rate card.

Credentials

AI, distributor and search API keys are stored as server-side secrets. They are never shipped to the browser and never written into proposal data or logs. Secret values are redacted from error output.

Transport and storage

All traffic is served over HTTPS. Uploaded brief PDFs are stored in access-controlled object storage bound to your account.

Integrity of pricing

Supplier prices carry their source, URL or reference and timestamp. Export is blocked when pricing is stale, unresolved or when quote inputs changed after pricing, so a proposal cannot be issued on numbers nobody verified.

Reporting a vulnerability

Report security issues to security@anvilpaper.com. Please include reproduction steps and give us reasonable time to fix before disclosure.

Questions? Contact us.